Insufficient verification of data authenticity in Apache APISIX - CVE-2026-44087
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to protected resources.
The vulnerability exists due to insufficient verification of data authenticity in the openid-connect plugin when processing identity headers under the default configuration. A remote attacker can spoof identity headers to gain unauthorized access to protected resources.
Only the default configuration of the openid-connect plugin is affected.